Files
buildroot/package
Thomas Perale 4e73a15a7b package/unzip: patch CVE-2021-4217
The patch is provided thanks to the Ubuntu community.

- CVE-2021-4217:
    A flaw was found in unzip. The vulnerability occurs due to improper
    handling of Unicode strings, which can lead to a null pointer
    dereference. This flaw allows an attacker to input a specially crafted
    zip file, leading to a crash or code execution.

For more information, see:
 - https://www.cve.org/CVERecord?id=CVE-2021-4217
 - https://launchpadlibrarian.net/580782282/0001-Fix-null-pointer-dereference-and-use-of-uninitialized-data.patch
 - https://bugs.launchpad.net/ubuntu/+source/unzip/+bug/1957077

Signed-off-by: Thomas Perale <thomas.perale@mind.be>
[Peter: correct _IGNORE_CVES entry]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2026-06-03 09:58:10 +02:00
..
2026-05-30 19:23:32 +02:00
2026-05-31 08:30:36 +02:00
2026-05-29 10:32:34 +02:00
2026-05-30 10:57:38 +02:00
2026-05-30 12:43:00 +02:00
2026-05-30 10:57:37 +02:00
2026-05-24 19:42:11 +02:00
2026-05-30 11:00:04 +02:00
2026-05-29 23:04:14 +02:00
2026-06-01 11:26:32 +02:00
2026-05-30 10:57:38 +02:00
2026-05-30 12:49:39 +02:00
2026-05-29 15:45:52 +02:00
2026-06-03 09:58:10 +02:00
2026-05-29 16:33:35 +02:00
2026-05-31 19:38:29 +02:00
2026-05-31 13:12:45 +02:00
2026-06-01 21:36:35 +02:00